How to Use Google Authenticator Without Losing Access
Short answer
Install Google Authenticator, scan the QR code the service shows you, then enter the six-digit code to confirm. Before you leave that setup screen, save the recovery codes the service offers and turn on cloud sync in the app's settings. Without one of those two, a lost phone means recovering every account individually.
On this page
Google Authenticator is the default recommendation for a reason, and also the most common way people lock themselves out of their own accounts. The app is fine. The problem is that the dangerous part of the process happens in about four seconds, on a screen most people skip past.
Here is the setup done in the order that survives a lost phone, rather than the order the prompts put it in.
What the app is actually doing
When you scan a QR code, you are not pairing with a server. That QR encodes a shared secret, and the app stores it locally. From then on, both the app and the service run the same calculation — the secret, plus the current time rounded to a 30-second window, and arrive at the same six digits independently.
Three consequences follow from that, and they explain almost every question people have:
- No internet is needed. The phone is doing arithmetic, not fetching a code.
- The clock matters enormously. If your phone’s time drifts, the codes stop matching.
- The secret cannot be recovered from the service. Google cannot resend it. Once it is only on a phone that is gone, it is gone.
This is also why the app works with services that have nothing to do with Google. It implements an open standard called TOTP, so any TOTP app handles any TOTP account.
Set it up in the right order
Pick one service to start with, and ideally not your main email — do a less critical account first so a mistake is cheap.
- Install the app. Google Authenticator on the App Store or Play Store. Check the publisher is Google; the stores carry convincing imitations.
- Turn on cloud sync first. Open the app, tap your profile icon, and sign into a Google account. The app then backs the secrets up to that account. Doing this before you add anything means every account you add is covered.
- Open the service’s 2FA settings. Usually under Security, Sign-in, or Account. Choose the authenticator app option rather than SMS.
- Scan the QR code with the app’s + button → Scan a QR code.
- Type the six-digit code back into the service to confirm the pairing. If you skip this, 2FA is not actually enabled.
- Save the recovery codes. This is the step that matters. Keep reading.
Do not leave the setup page without the recovery codes
Nearly every service shows a set of single-use backup codes during or just after 2FA setup. They are the officially supported way back in when the app is gone.
Save them before you close that page. Most services display them once. A few let you regenerate them later, but only while signed in, which is exactly the state you will not be in when you need them.
Put them somewhere that is not the phone running the app and not inside the account they unlock. Where to keep recovery codes covers the options honestly, including why a screenshot in your photo library is worse than it sounds.
The manual key, for when the camera route fails
Every QR code screen has a “can’t scan it?” link revealing a long text string. That string is the secret. You can type it into the app manually under Enter a setup key.
It is also something to handle carefully: anyone who photographs that screen can add your account to their own authenticator and generate valid codes indefinitely. Treat the QR code and the manual key as being as sensitive as the password itself.
What cloud sync does and does not cover
Google Authenticator’s sync feature backs your secrets up to a Google account. It solves the most common disaster, which is dropping the phone down a drain, and it is worth turning on.
It does not solve everything:
| Scenario | Sync helps? |
|---|---|
| New phone, same Google account | Yes, codes restore on sign-in |
| Phone lost or broken | Yes |
| Locked out of the Google account holding the sync | No |
| You put your Google 2FA inside this app and lost the phone | No, circular |
| Switching to a different authenticator app | No, no export to third parties |
That fourth row is the trap. If your Google account’s own second factor lives only in Google Authenticator, and the Authenticator backup lives in that same Google account, then losing the phone leaves you unable to reach either. Make sure your Google account has a second route: a passkey, a second device, or printed backup codes stored elsewhere.
Moving to a new phone
Do this before wiping the old one, which sounds obvious and is routinely ignored.
With sync on: install the app on the new phone, sign into the same Google account, and the accounts appear. Confirm a code works on a real login before you factory-reset the old phone.
Without sync: use the export feature. On the old phone, tap the menu → Transfer accounts → Export accounts, choose which to move, and the app produces a QR code. Scan it from the new phone’s import screen. Large numbers of accounts produce several QR codes in sequence.
That export QR contains every selected secret in plain form. Do not photograph it, do not screenshot it, and do not display it anywhere a camera can see.
If the old phone is already gone: there is no transfer. Each account must be recovered through its own provider, which is what recovering an account without your authenticator is about, and the outcome is not guaranteed.
When codes stop being accepted
The app says the code is valid, the site says it is wrong. Three causes, in order of likelihood.
Clock drift. The phone’s clock has slipped relative to real time. Set Settings → General → Date & Time → Set Automatically on iPhone, or Settings → System → Date & time → Set time automatically on Android. Google Authenticator on Android also has a Time correction for codes option in its settings that resyncs without touching the system clock.
Typing it after it expires. The code rotates every 30 seconds. If the coloured timer is nearly empty, wait for the next one rather than rushing.
The wrong entry. Several accounts from the same provider look identical in the list. Check the email address under the account name.
What to avoid
- Screenshotting the QR code “as a backup”. It sits in your photo library, which is probably synced to a cloud account, which may be protected by the same 2FA that QR code sets up.
- Enabling 2FA on ten accounts in one sitting. You will not save ten sets of recovery codes properly. Do two or three, then stop.
- Removing SMS as a backup before the app is confirmed working. Sign out and back in once with the app first.
- Relying on a single phone. A second device with the same secrets, or a password manager that also stores TOTP codes, costs nothing and removes the single point of failure entirely.
Realistic expectations
Set up properly, the app is nearly invisible. Most services only ask for a code on a new device or after months away, so a typical person opens the app a handful of times a year.
The failure mode is not the app breaking. It is a new phone, a factory reset, or a drowned handset combined with recovery codes nobody saved. Spend the extra sixty seconds on sync and the codes now, because the version of you that needs them will have no other option. Once your accounts are set up, it is also worth checking which devices are signed in to confirm nothing predates the change.